Category Started On Completed On Duration Cuckoo Version
FILE 2014-01-24 13:34:28 2014-01-24 13:36:44 136 seconds 1.0

File Details

File name zeus2.exe
File size 47616 bytes
File type MS-DOS executable
CRC32 58F93697
MD5 ebbe29d74e03003ffaaadc4edf11d6da
SHA1 68b5b85fba79654535cd130027fc873f80c66284
SHA256 2eeff130bf652d04638e599f1313b7748d83b54ae91dd9c3414002e0f9e9864c
SHA512 136c0831a538c22bebb5cf09a2446dfceabefa1b1b2822ead43110d28df5d5d1f731647ed77e0de47f09df1be219f99dab90a53c401a3eb1a75476ca0208f6c2
Ssdeep 768:Q9SvSmis1Cd5BSAeS1df0FB0Wgo75GpaSoabxN+bsEDYgO0MfxagFEmKO+hUu:a0SPsMHPeid6B0w75GpaS8sdgO0MxEmU
PEiD None matched
Yara None matched
VirusTotal VirusTotal lookup disabled, add your API key to the module

Signatures

No signatures matched

Screenshots

Static Analysis

Nothing to display.

Dropped Files

Nothing to display.

Network Analysis

Hosts Involved

Behavior Summary

Files
  • C:\WINDOWS\system32\ntos.exe
  • C:\WINDOWS\system32\ntdll.dll
  • PIPE\lsarpc
Mutexes
  • C:\__SYSTEM__91C38905__
  • C:\__SYSTEM__64AD0625__
  • C:\__SYSTEM__7F4523E5__
Registry Keys
  • HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\

Processes

registry filesystem process services network synchronization

zeus2.exe PID: 432, Parent PID: 508

Volatility

Nothing to display.